CVE-2026-20253 PoC — Splunk Cloud Platform和Splunk Enterprise 访问控制错误漏洞
关联漏洞
标题:
Splunk Cloud Platform和Splunk Enterprise 访问控制错误漏洞
(CVE-2026-20253)
Description:Splunk Cloud Platform和Splunk Enterprise都是美国Splunk公司的产品。Splunk Cloud Platform是一个强大的数据收集、处理和分析服务。Splunk Enterprise是一套数据收集分析软件。 Splunk Enterprise 10.2.4之前版本和10.0.7之前版本、Splunk Cloud Platform 10.4.2604.3之前版本和10.2.2510.14之前版本存在访问控制错误漏洞,该漏洞源于PostgreSQL sidecar服务
Description
In Splunk Enterprise versions below 10.2.4 and 10.0.7, and Splunk Cloud Platform versions below 10.4.2604.3 and 10.2.2510.14, an unauthenticated user could create or truncate arbitrary files through a PostgreSQL sidecar service endpoint.<br><br>The vulnerability exists because the PostgreSQL sidecar service endpoint lacks authentication controls, allowing any network-reachable user to invoke file operations without credentials.
文件快照
备注
1. 建议优先通过来源进行访问。
2. 本地 POC 快照面向订阅用户开放;当原始来源失效或无法访问时,本地镜像作为订阅权益的一部分提供。
3. 持续抓取、验证、维护这份 POC 档案需要不少投入,因此本地快照已纳入付费订阅。您的订阅是让这份资料能继续走下去的关键,由衷感谢。 查看订阅方案 →